URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 23.241.17.95
Firstseen:2024-08-12 18:11:03 UTC
Total malware sites :7
Online malware sites :7 (100%)
Offline Malware sites :0 (0%)
Newest active malware site :2025-12-23 09:12:28 UTC
Oldest active malware site :2024-08-12 18:11:14 UTC (Age: 1 year, 9 month, 22 days, 19 hours, 49 minutes)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2024-08-12 18:11:14 23.241.17.95syn-023-241-017-095.res.spectrum.comNot listedAS20001 TWC-20001-PACWEST- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-12-23 09:12:28http://23.241.17.95/info.zipOnlineCoinMiner Riordz
2025-12-23 09:12:27http://23.241.17.95/video.scrOnlineCoinMiner Riordz
2025-12-23 09:12:27http://23.241.17.95/av.scrOnlineCoinMiner Riordz
2025-12-23 09:12:11http://23.241.17.95/photo.lnkOnlineCoinMiner Riordz
2025-12-23 09:12:11http://23.241.17.95/av.lnkOnlineCoinMiner Riordz
2025-12-23 09:12:11http://23.241.17.95/video.lnkOnlineCoinMiner Riordz
2024-08-12 18:11:14http://23.241.17.95/Photo.scrOnlineCoinMiner exe iframe Photo.scr scr NDA0E